CVE-2026-29145
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Atlassian products to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
- Who is affected
- Users of Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management are affected.
- Urgency
- Remediation is high urgency due to the potential for severe exploitation and active attacks.
- Action
- Update all affected Atlassian products to the latest versions immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-29145
Get an email if CVE-2026-29145 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Advisory coverage (7)
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund · 2026-08-14
- unknownexploitedMultiple vulnerabilities in IBM products (August 14, 2026)cert-fr-avis · 2026-08-14
- highexploited[UPDATE] [medium] Apache Tomcat and Tomcat Native: Multiple vulnerabilitiescert-bund · 2026-08-05
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis · 2026-07-31
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis · 2026-07-27
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis · 2026-07-24
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund · 2026-07-20
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-29145)